Resource icon

Run Microsoft Defender Offline and verify what it actually found

Persistent malware can interfere with scans while Windows is running. Microsoft Defender Offline restarts into the Windows Recovery Environment, scans before the normal desktop loads and then starts Windows again. The screen changing or a restart finishing is not proof that a threat was removed. This guide treats the scan as one step in a response: preserve evidence, run the official option, read the result and decide what to do if symptoms continue.

Before you start​

Save work and back up essential files without copying suspicious executables. Keep the BitLocker recovery key available and connect a laptop to power. Update Windows Security definitions while online if possible. If you suspect account theft, use a different trusted device to change critical passwords and revoke sessions; a scan on the affected PC cannot secure remote accounts.

Do it step by step​

  1. Open Windows Security > Virus & threat protection > Scan options and choose Microsoft Defender Antivirus (offline scan). Confirm the PC will restart.
  2. Allow the recovery environment scan to finish. Do not force power off because the display appears quiet for a while; note any error or recovery prompt.
  3. After Windows starts, open Windows Security > Protection history and read the latest action. Record the threat name, path, action and time if a detection exists.
  4. Run a normal updated scan and inspect startup apps, browser extensions and scheduled tasks only if symptoms suggest persistence. Do not delete random system files from a search result.
  5. If malware was found, isolate sensitive accounts and assess whether personal data was exposed. Restore affected documents from a known-good backup after the system is clean.
  6. If no threat appears but symptoms remain, gather logs, compare other user profiles and consider a supported repair or clean installation after backing up data.

Check the result​

Protection history shows the scan outcome or actionable error, and the original symptom has either stopped or has a documented next investigation step.

If something goes wrong​

If the offline scan cannot start, check recovery environment health and encryption prompts. If security software from another vendor is active, follow its supported scan path. A repeated serious detection warrants professional incident response or reinstall from trusted media.

Know the limit​

A clean scan is not proof that no compromise occurred. Offline scanning focuses on malware detection; it does not undo stolen credentials, data exfiltration or malicious browser permissions. Microsoft Defender Offline Protection history

Decision checkpoint​

Choose an offline scan when persistence is plausible or Microsoft recommends it, not as a daily ritual. If only one downloaded file is suspect, a targeted scan and provenance review may be faster. If there is evidence of account takeover, scanning the disk is not enough; secure accounts and sessions separately. If sensitive work files may have been copied, preserve logs before a reinstall and follow the organization's incident process.

Aftercare​

If the machine is shared, tell other users what symptom prompted the scan and ask them to report recurring pop-ups or new sign-in prompts.
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack